CVE-2026-25935
Vikunja is a todo-app to organize your life. Prior to 1.1.0, TaskGlanceTooltip.vue temporarily creates a div and sets the innerHtml to the description. Since there is no escaping on either the server or client side, a malicious user can share a project, create a malicious task, and cause an XSS on hover. This vulnerability is fixed in 1.1.0.
Vendor
Product
CWE
Yayın Tarihi
2026-02-11 21:16:20
Güncelleme
2026-02-20 20:17:54
Source Identifier
security-advisories@github.com
KEV Date Added
-